DLL Load By System Process From Suspicious Locations

 Original Source: [Sigma source]
Title: DLL Load By System Process From Suspicious Locations
Status: test
Description:Detects when a system process (i.e. located in system32, syswow64, etc.) loads a DLL from a suspicious location or a location with permissive permissions such as "C:\Users\Public"
References:
  -https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC (Idea)
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-17
modified:2023-09-18
Tags:
  • -'attack.stealth'
  • -'attack.t1070'
Logsource:
  • product: windows
  • category: image_load
Detection:
  selection:
    Image|startswith: 'C:\Windows\'
    ImageLoaded|startswith:
      -'C:\Users\Public\'
      -'C:\PerfLogs\'

  condition:selection
Falsepositives:
  -Unknown
Level: medium